Skip to main content
Version: 0.1 (next)

CRD reference

All kinds are in the API group infrared.darkshift.io, version v1alpha1. Cluster-scoped kinds describe the control plane. Namespaced kinds belong to one org and live in ir-org-<org>. Every kind has status.observedGeneration and status.conditions (Ready, Progressing, Degraded), which are left out of the tables below.

Resources Infrared creates carry the label app.kubernetes.io/managed-by: infrared. Org resources carry infrared.darkshift.io/org, and catalog-seeded resources carry infrared.darkshift.io/catalog.

KindShort nameScope
InstallationirinstCluster
OrganizationirorgCluster
ClusterirclusterCluster
GitProviderirgitir-org-<org>
GitopsRepoirgitopsir-org-<org>
Productirproductir-org-<org>
AgentRolearir-org-<org>
AgentWorkflowawir-org-<org>
AgentWorkflowRunawrir-org-<org>

Installation​

The singleton that tracks the setup wizard. It must be named infrared. The API fills in the spec as the wizard advances; the controller derives the phase.

FieldMeaning
spec.tokenVerifiedSet once the one-time setup token has been presented.
spec.admin.email, spec.admin.passwordSecretRefThe first platform admin and the Secret key holding the bcrypt hash of their password.
spec.platformOrgThe Organization that administers the control plane.
spec.managementClusterThe Cluster Infrared runs on.
spec.gitProviderRef, spec.gitopsRepoRefThe platform org's GitProvider and GitopsRepo.
status.phaseAwaitingToken, AwaitingAdmin, AwaitingOrg, AwaitingCluster, AwaitingGitProvider, AwaitingGitopsRepo, Syncing or Ready.
status.versionThe Infrared control plane version.

Organization​

An org: the tenancy and RBAC boundary. Names are at most 56 characters so ir-org-<name> fits a namespace.

FieldMeaning
spec.displayNameName shown in the UI.
spec.platformTrue for the org that administers the control plane.
spec.clusterAllowlistClusters this org may deliver zones to. Managed by the platform org.
status.namespaceThe org's namespace, ir-org-<name>.

Cluster​

A management or workload cluster.

FieldMeaning
spec.typemanagement or workload.
spec.flavork3s or eks. Selects distribution-specific components.
spec.provider, spec.regionaws, gcp, linode or local, and the provider region.
spec.template.module, spec.template.versionThe cluster template (a module in infrared-iac-modules, such as aws/k3s-node) and its tag.
spec.serverAPI server URL Argo CD uses. Empty means in-cluster.
status.kubernetesVersion, status.nodesObserved version and node count.
status.detectedTrue for the cluster Infrared found itself running on.

GitProvider​

Connects an org to GitHub through a GitHub App. GitLab and Gitea come later.

FieldMeaning
spec.typegithub-app.
spec.ownerThe GitHub organization login Infrared manages.
spec.github.appID, spec.github.slugThe GitHub App.
spec.github.installationIDSet once the App is installed on the owner.
spec.github.privateKeySecretRefSecret key holding the App's PEM private key.
spec.github.webhookSecretRefSecret key holding the webhook secret.
spec.github.apiURLOverrides https://api.github.com for GitHub Enterprise Server.
status.installationVerified, status.lastVerifiedTimeWhether and when the App last minted an installation token.

GitopsRepo​

An org's gitops repo, created, hydrated and bootstrapped by Infrared.

FieldMeaning
spec.providerRefThe GitProvider that owns the repo.
spec.name, spec.visibility, spec.defaultBranchDefaults gitops, private, main.
spec.template.repo, spec.template.versionThe gitops template and the tag it is hydrated from.
spec.cluster, spec.clusterFlavorThe management cluster the registry bootstraps, and its flavor.
spec.bootstrapApply Argo CD and the root Application after hydration. Default true.
status.phasePending, Created, Hydrated, Bootstrapped or Synced.
status.url, status.commit, status.hydratedVersionThe repo URL, the last hydration commit and the template version used.
status.waves[]Per sync wave, each Application's sync (Synced, OutOfSync, Unknown) and health (Healthy, Progressing, Degraded, Suspended, Missing, Unknown).

Product​

The unit Infrared builds, releases and manages change for.

FieldMeaning
spec.displayName, spec.descriptionShown in the UI.
spec.repos[]The repos in the Product: owner, name and role (app, chart, umbrella, library or docs).
spec.currentReleaseThe Release in progress, such as 2.4.
spec.logorepo (default: the first repo) and path (default: found by convention). See Products.
status.logorepo, path, sha, contentType, bytes, source (detected or uploaded), syncedAt, pending, message.

AgentRole​

A job an agent performs. See AgentRoles, AgentWorkflows and AgentWorkflowRuns.

FieldMeaning
spec.displayName, spec.summaryName and one-sentence summary (at most 280 characters).
spec.categoryarchitect, change-review, scheduled or builder.
spec.missionThe outcome the role is accountable for.
spec.responsibilities[]Ordered steps.
spec.triggers[]type (adhoc, onChange, cron, event), schedule, event, description, and optional filters labels[], paths[] (globs) and branches[].
spec.inputs[]source and description.
spec.outputs[]What the role leaves behind.
spec.evidence[]kind (screenshot, video, report, log, comment, diff, sarif, metric, document, trace, sbom), description, required.
spec.successCriteria[]Verifiable statements that must all hold.
spec.guardrails[]What the role must never do.
spec.permissionsallowedTools, deniedTools, git, cluster, network (none, allowlist, open), egressAllowlist, mayMerge. Deny wins over allow. egressAllowlist may contain $(ZONE_HOSTS), which the runner expands to the Product's zone hostnames.
spec.escalationwhen[], to (a team or user handle), after (a duration such as 30m).
spec.opinions[]name, title, guidance, origin (catalog, org, tailored), enabled (omitted means on; false keeps the opinion but the agent doesn't receive it).
spec.verdicts[]The verdicts a run may end with, such as VERIFIED, MERGE WITH FOLLOW-UPS, BLOCK. Every run ends with exactly one.
spec.instructionsMarkdown appended to the role's prompt for the org.
spec.skills[], spec.mcpServers[]Names of skills and MCP servers the org configured for the role.
spec.modelproviderRef, model, maxBudgetUSD (decimal string), maxTurns.
spec.enabledWhether the role runs.
spec.origincatalog version, tailored, tailoredFrom[].
status.statsruns7d, succeeded7d, medianTokens, lastRunTime.
status.differsFromCatalogTrue when the org edited the role after seeding.

AgentWorkflow​

Orders AgentRoles and gates into a repeatable workflow.

FieldMeaning
spec.displayName, spec.descriptionShown in the UI.
spec.triggers[]Same shape as AgentRole triggers.
spec.steps[]name, type (agentRole, human, auto, ci, promote), agentRole, zone, required, onFailure (deadLetter, fail, continue), maxAttempts, needs[], independent, when, approvers[], minApprovals, timeout, description. Empty needs means the previous step; independent: true starts the step with the workflow. when is a condition such as change.author in [human], agentRole.enabled or label:security, combined with && and negated with !. approvers, minApprovals (default 1) and timeout configure human gates; timeout applies to any step. A step whose AgentRole is switched off is Skipped.
spec.deadLetterto (default human reviewer) and notify[] channels such as slack:#checkout-changes.
spec.maxConcurrencyRuns at once. Default 3.
spec.enabled, spec.originAs for AgentRole.

AgentWorkflowRun​

One run of an AgentWorkflow. Execution arrives in phase 5.

FieldMeaning
spec.workflowRef, spec.productRefThe AgentWorkflow and the Product.
spec.changerepo, issue (such as checkout-web#212) and pullRequest.
spec.triggerWhat started the run, such as onChange, cron or adhoc:<user>.
status.phaseQueued, Running, DeadLettered, AwaitingApproval, Succeeded, Failed, Cancelled or Skipped.
status.steps[]Per step: phase, verdict, attempts, startedAt, finishedAt, usage, evidence[] (with per-criterion results) and message.
status.usageInput, output and cache-read tokens, costUSD and turns for the whole run.